Re: Alert: Microsoft Security Bulletin - MS03-017

From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 05/07/03

  • Next message: Jouko Pynnonen: "Windows Media Player directory traversal vulnerability"
    Date:         Wed, 7 May 2003 15:26:50 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Unfortunately it would appear that Microsoft Security Response Center has lost all of the people capable of making reasonable statements regarding, in this case, Mitigators.

    From MS03-017 - Mitigating factors

    "By default, Outlook Express 6.0 and Outlook 2002 open HTML mails in the Restricted Sites Zone. In addition, Outlook 98 and 2000 open HTML mails in the Restricted Sites Zone if the Outlook Email Security Update, has been installed. Customers who use any of these products would be at no risk from an e-mail borne attack that attempted to automatically exploit these vulnerabilities."

    This is extremely misleading. We have only had viruses for 8+ years now that rely upon users clicking on something in their email. Whether the attack was crafted to be automated or not, if a URL is present and the user chooses to click on it, it will be successful even if OE 6 or O2K are used, even if the Outlook Email Security Update is in place. Microsoft themselves acknowledge this in their Technical description section.

    "The attacker would have no way to force users to visit a malicious web site. Instead, the attacker would need to lure them there, typically by getting them to click on a link that would take them to the attacker's site."

    Obviously this is totally false, and they even say so in their own Technical description section;

    "However if the user was not using Outlook Express 6.0 or Outlook 2002 in their default configurations, or Outlook 98 or 2000 in conjunction with the Outlook Email Security Update, the attacker could cause an attack that could both place, then launch the malicious executable without the user having to click on a URL contained in an e-mail."

    Don't they read their own writings?

    Granted, they list it as "Critical", but then they should also ensure they are not totally misleading people who read the "Mitigating factors" section.

    For MS03-017, there's only one mitigating factor MS can offer...make sure you're running Media Player 9.0 (and by the way, it doesn't matter whether its running or not, or whether its ever been used, if something tries to invoke it you will be happily walked through a wizard to get it running...its on every system unless you purposefully removed the binaries!)

    Cheers,
    Russ - NTBugtraq Editor

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Delivery co-sponsored by IP3 Inc.
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    SECURITY QUESTIONS? We've got answers...Apply for a scholarship and become
    TICSA certified.

    Do not miss your opportunity to discover solutions to what our participants
    have identified as their top 5 IT Security Challenges. You will return to
    work better prepared to put into place an effective security strategy
    utilizing the latest security tools, bookmarks and URL's.

    <http://www.ip3seminars.com>

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: Jouko Pynnonen: "Windows Media Player directory traversal vulnerability"

    Relevant Pages

    • [NT] Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (MS03-044)
      ... Get your security news from a reliable source. ... A security vulnerability exists in the Help and Support Center function ... *Microsoft Windows Millennium Edition ... An attacker could exploit the vulnerability by constructing a URL that, ...
      (Securiteam)
    • [UNIX] Security Analysis of VTun
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... An attacker can modify ... Packet forwarding: ... password) as encryption key. ...
      (Securiteam)
    • [REVS] Security Considerations for Web-based Applications
      ... Get your security news from a reliable source. ... consequences of this ranges from the erosion of customer confidence in the ... of poorly implemented host naming procedures or web-application URL ... The attacker may choose to inject ...
      (Securiteam)
    • [NT] Windows Media Player Directory Traversal Vulnerability (WMZ)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... When Media Player 7 or 8 is installed, ... As most other Internet Explorer vulnerabilities, ... cannot be guessed by a potential attacker. ...
      (Securiteam)
    • [NT] MHTML vulnerability in Outlook Express
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in Outlook Express allows an attacker to run code of the ... If an attacker were to host a malicious website that contained an MHTML ...
      (Securiteam)